Executive brief
decamelize is a JavaScript library that converts camelCase strings into kebab-case format. The library is vulnerable to regular expression denial of service (ReDoS) attacks when processing untrusted input, allowing an attacker to cause the application to hang or consume excessive CPU resources by supplying specially crafted strings.
Technical details
The vulnerability is a regular expression denial of service (ReDoS, CWE-400) caused by an unvalidated separator parameter being passed directly into a regex pattern without proper escaping. When a user supplies a special regex metacharacter (such as the pipe "|") as the separator argument, it creates a malicious regular expression that exhibits catastrophic backtracking. An attacker can trigger this via network if the affected library processes user input without sanitization. The vulnerability affects versions 1.1.0 through 1.1.1; patched in version 1.1.2 and later.
Affected products
- sindresorhus decamelize 1.1.0 through 1.1.1
Timeline
- 2015-12-23: disclosed: Issue reported on GitHub
- 2018-07-24: advisory: GHSA advisory published
- 2017: patched: Fixed in version 1.1.2